Impact
A flaw in Keycloak's organization management component allows a delegated administrator who has invitation for a non‑existent e‑mail address. The administrator can then retrieve the programmatic invitation link. With that link the administrator can create new user accounts and add them to the organization, bypassing the required user‑management permissions and the need to access the invited e‑mail account. This effectively lets an administrator add unauthorized members to an organization, breaking the intended security boundaries. This constitutes a CWE‑284 Authorization Bypass using Improper Authorization weakness.
Affected Systems
This vulnerability affects Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat Data Grid 8, and Red Hat JBoss Enterprise Application Platform Expansion Pack. The specific affected versions are not listed in the CNA data; any installation that has not yet applied the vendor‑remediated update is vulnerable.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score of < 1 % indicates a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires a user to already possess delegated administrator privileges for organization management, so the attack vector is internal and limited to environments where such authorities exist. If an attacker can retrieve the invitation link, they can elevate their own account privileges within that organization, enabling further unwanted actions.
OpenCVE Enrichment